DeluxeBB Multiple Vulnerabilities
BID:37448
Info
DeluxeBB Multiple Vulnerabilities
| Bugtraq ID: | 37448 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2009 12:00AM |
| Updated: | Dec 28 2009 10:13PM |
| Credit: | cp77fk4r |
| Vulnerable: |
DeluxeBB DeluxeBB 1.3 |
| Not Vulnerable: | |
Discussion
DeluxeBB Multiple Vulnerabilities
DeluxeBB is prone to multiple vulnerabilities, including a cross-site-scripting issue, an authentication-bypass issue, and multiple security-bypass issues.
Attackers can exploit these issues to gain administrative access to the affected application, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or perform restricted actions.
DeluxeBB 1.3 is vulnerable; other versions may also be affected.
DeluxeBB is prone to multiple vulnerabilities, including a cross-site-scripting issue, an authentication-bypass issue, and multiple security-bypass issues.
Attackers can exploit these issues to gain administrative access to the affected application, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or perform restricted actions.
DeluxeBB 1.3 is vulnerable; other versions may also be affected.
Exploit / POC
DeluxeBB Multiple Vulnerabilities
Attackers can use a browser to exploit these issues. In order to exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into following a crafted link.
The following example URIs are available:
Attackers can use a browser to exploit these issues. In order to exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into following a crafted link.
The following example URIs are available:
Solution / Fix
DeluxeBB Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].